THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81766 — The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to inst

[NVD] CVE-2026-81766 — The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to inst

mednvdPublished 2026-08-30

CVE-2026-81766 CVSS: None Published: 2026-08-30T07:17:21.890

The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the network-shared Real

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81766